Blog · AI Strategy

How to Build an AI Tool Approval Process

An AI tool approval process needs to cover software you already own, because most AI now arrives as a feature switched on inside tools you bought years ago. Decide by what data goes in rather than by the tool, and treat how a vendor answers a hard question as the answer itself.

A printed checklist on a desk under a warm lamp, one line ticked in teal, a hand holding a pen beside it.

In the fall of 2025 we were answering the same questions from clients as we were for ourselves. Can we use this new tool. What about this one. Is this one safe. It came often enough that we stopped answering it case by case and built an AI tool approval process we could actually run, along with a small internal tool, Polly-C, that goes and reads what a vendor says about privacy, training, and what happens to your data.

Using AI to make better decisions about AI is a slightly ridiculous sentence to write. Polly-C is also one of the most-used internal tools we have.

The question is not the one most people are answering

Most AI does not arrive as a purchase. It arrives switched on.

The obvious half of the job is the well-known assistants, and clients do ask about those by name. The half that catches people is the software they already pay for. Your chat platform adds an assistant. Your presentation software adds generation. Your CRM starts summarizing calls. Nobody bought anything, no procurement process ran, and a tool that has had your data for three years is now doing something new with it.

An AI tool approval process that only covers new purchases will miss most of what actually needs deciding.

What a vendor does with a hard question

How a vendor answers is the answer.

We wanted to use an AI presentation tool. We were in its early adopter group, which meant we had a direct line to ask, and when we read the privacy policy and the terms we could not tell whether they trained on customer content. Not a red flag exactly. An unanswered question.

So we used it, and kept anything with client information out of it, and asked. They came back with a clear answer for the group, and then published an update saying the same thing publicly. We have been happy customers since, and more than that, we trust them with work we would not have given them before.

Put that next to a tool creator who was told their platform trains on their customers’ data and replied that the plan which stops it was expensive. Same question, two answers, and the answers tell you everything the marketing pages do not.

What our AI tool approval process checks

Five things, and the order matters because the cheap checks eliminate most candidates.

  • What the privacy policy and terms actually say about training, retention, and sub-processors, and whether they exist at all
  • Whether the paid tier changes any of that, since paying is not the same as opting out
  • What access the tool is asking for, and what that access would allow at its worst
  • Who is behind it, and whether they have a findable track record
  • Whether a clear answer is available at all, because an unanswered question is itself a result

Why our policy will not work for you

Because an AI tool approval process depends on your data, not on the tool.

A company handling patient records, a firm handling investment data, and a local sports association can all be looking at the same assistant and reach three different correct answers. The regulations differ, the customer promises differ, and the cost of being wrong differs by orders of magnitude.

This is why “which AI tools are safe” has no general answer, and why lists of approved tools go stale the moment someone’s use case shifts. The durable version is a policy about what data may go where, with the tool list as an output of it rather than the substance.

What does a small company actually need?

A published list and one person who decides. That is genuinely enough for a firm of a dozen.

Ours is a straightforward policy saying which tools may be used and for what. It is short, it is written down, and people can read it before they need it rather than after. For clients we go further and keep the policy, the guidance, and the approved list in one place, because at a couple of hundred people the Slack-message version stops working.

The failure mode worth avoiding is an AI tool approval process slow enough that people route around it. A month-long review does not stop anyone using a tool. It moves the tool onto a personal laptop where nobody can see it, which is strictly worse than the thing the review was protecting you from.

Frequently Asked Questions

Should we just ban AI tools until we have a process?

No, and blanket bans reliably produce the outcome they are meant to prevent.

People still have the work to do and the tools are a browser tab away. A ban with no approved alternative moves the activity somewhere you cannot see, audit, or support. Publish a short list of what is allowed today, even if it is three tools, and expand it as you evaluate.

How do we keep up when vendors change terms?

Assume they will, and check the ones that matter on a schedule.

New AI features ship constantly and often arrive enabled. Put a recurring review on the tools holding your most sensitive data rather than trying to watch everything, and treat any vendor announcement about a new AI capability as a prompt to re-read what you agreed to.

Who should own the AI tool approval process?

Someone who can say yes quickly.

The specific role matters less than the response time. If the person who decides is unreachable for a week, the process is decorative. In a small company this is usually a founder. In a larger one it works best as a named person with a documented standard rather than a committee.

What if a vendor will not answer clearly?

Treat that as the answer and keep sensitive data out until it changes.

You do not need a confrontation or a decision to stop using the tool. Use it for work where the answer would not matter, ask the question, and expand what you put in once you have something clear in writing.

The part nobody writes down

The tools change monthly and the reading is genuinely tedious.

That is the actual reason most companies have no AI tool approval process: not disagreement about what matters, just nobody with the hours to keep up. It is why we built Polly-C to do the reading for us, and why the engagements we run increasingly include this rather than treating it as paperwork alongside the real work.

A note on frameworks, since someone always asks. The NIST AI Risk Management Framework is the reference an auditor or an enterprise customer is most likely to recognize, so the name is worth knowing. Adopting the whole thing is not the first move for a company of a dozen people, and we would not suggest it. One written page about what data may go where will do more for you this quarter.

If you are trying to work out what your team should be allowed to use, tell us what you are working on.

Book your AI Business Impact Assessment

One conversation. We learn how your business operates and find where AI can have the biggest impact. No commitment beyond the conversation.

Book your assessment